Malware

Generik.KPXEJHN removal tips

Malware Removal

The Generik.KPXEJHN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KPXEJHN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
smart.cloudnetwork.kz
static.apiinformation.kz
secure.jscontentmaker.kz
secure.jsc0nten1maker.com
static.apiinformationsec.com
mel.cloudcontentsmak.com
nicru.supermicrotransapi.ru
tel.jsapisettings.kz
js.securetopdevelopment.kz
noone.contentmakersbyakamai.ru

How to determine Generik.KPXEJHN?


File Info:

crc32: E35FBAD6
md5: 24c3cf820cf8aa66d7237716cab2414a
name: 24C3CF820CF8AA66D7237716CAB2414A.mlw
sha1: d65c68001848f2003014bc8a3e0742960753557c
sha256: ea10359d601c6aecd46a350cecfebadafb58ba3d596002a1e75b53298a51399e
sha512: 668e2c2afbec1fd91ed3c8ce5d614559b3214504e910c5cfa3fcdc3477da6c129f9bdf6db6d658a228a0a5e82c0d72fd447c607f9cfd897663f2b2e4f4579646
ssdeep: 12288:QseO2Ron3a05FghzjipadnPEoN7m+7uN3etJpMADL:Qi2Sa05FIjRN737uUJBL
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) 2007-2015
FileVersion: 8.6.8.6
CompanyName: RRC Group
FileDescription: Procure Southern
LegalTrademarks: (C) 2007-2015
Comments: Procure Southern
ProductName: SaleReplacement
ProductVersion: 8.6.8.6
PrivateBuild: 8.6.8.6
OriginalFilename: SaleReplacement
Translation: 0x0409 0x04b0

Generik.KPXEJHN also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Foreign.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Scarab.43
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.189370
AlibabaRansom:Win32/Foreign.6913510a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.20cf8a
CyrenW32/FakeAlert.OL.gen!Eldorado
SymantecTrojan.Silentbrute.B
ESET-NOD32a variant of Generik.KPXEJHN
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.oaex
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.RiskGen.fejbxo
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Trojan.Foreign.Hryx
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
ComodoMalware@#gsc2i5hqfxjh
BitDefenderThetaGen:NN.ZexaF.34110.zmKfa8EqiUbi
VIPRETrojan.FakeAlert
McAfee-GW-EditionGeneric.dve
FireEyeGeneric.mg.24c3cf820cf8aa66
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.ern
AviraHEUR/AGEN.1120572
Antiy-AVLTrojan/Generic.ASMalwS.26A48E7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/StopCrypt!ml
ArcabitTrojan.Ransom.Scarab.43
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Malware/Win32.Generic.C2571335
McAfeeGeneric.dve
MAXmalware (ai score=84)
PandaTrj/GdSda.A
IkarusTrojan.SuspectCRC
FortinetW32/Foreign.OAEX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.KPXEJHN?

Generik.KPXEJHN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment